Impact
In the Buy Now Plus plugin, the shortcode attributes are not properly sanitized or escaped, enabling a stored XSS flaw. An authenticated attacker who can add or edit content with Contributor-level access can embed malicious script code in the shortcode. Whenever a visitor loads a page that includes the injected shortcode, the attacker's script runs in that visitor’s browser context, potentially stealing cookies, hijacking sessions, or performing actions on behalf of the authenticated user. The flaw affects the confidentiality, integrity, and availability of all site visitors who view the affected content.
Affected Systems
The vulnerability exists in the WordPress plugin Buy Now Plus from supercleanse, in all releases up to and including version 1.0.2. Users with Contributor or higher permissions on the affected WordPress site can create the malicious input.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate risk, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The flaw is not currently listed in CISA’s KEV catalog. An attacker would need to first authenticate as a Contributor or higher and modify content using the plugin’s shortcode functionality; no privilege escalation or network external attack is required. Because the impact is limited to users who view the compromised content, the attacker benefits mainly from user compromise rather than system compromise.
OpenCVE Enrichment